7.5

CVSS3.0

CVE-2025-3225 - XML Entity Expansion vulnerability in run-llama/llama_index

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS…

πŸ“… Published: July 7, 2025, 9:54 a.m. πŸ”„ Last Modified: July 30, 2025, 9:24 p.m.

7.1

CVSS3.1

CVE-2024-43334 - WordPress Zilom theme < 1.4.5 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gavias Zilom zilom allows Reflected XSS.This issue affects Zilom: from n/a through < 1.4.5.

πŸ“… Published: July 7, 2025, 9:53 a.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

6.1

CVSS3.1

CVE-2025-4779 - Stored Cross-site Scripting (XSS) in lunary-ai/lunary

lunary-ai/lunary versions prior to 1.9.24 are vulnerable to stored cross-site scripting (XSS). An unauthenticated attacker can inject malicious JavaScript into the `v1/runs/ingest` endpoint by adding an empty `citations` field, triggering a code path where `dangerouslySetInnerHTML` is used to rende…

πŸ“… Published: July 7, 2025, 9:53 a.m. πŸ”„ Last Modified: Dec. 3, 2025, 8:33 p.m.

6.9

CVSS4.0

CVE-2025-7122 - Campcodes Complaint Management System index.php sql injection

A vulnerability was found in Campcodes Complaint Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has bee…

πŸ“… Published: July 7, 2025, 9:32 a.m. πŸ”„ Last Modified: July 8, 2025, 6:29 p.m.

6.8

CVSS3.1

CVE-2025-3705 - OS Command Injection via USB Config Load

A physical attacker with no privileges can gain full control of the affected device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') when loading a config file from a USB drive.

πŸ“… Published: July 7, 2025, 9:20 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-3626 - OS Command Injection via Config Upload in WebUI

A remote attacker with administrator account can gain full control of the device due to improper neutralization of special elements used in an OS Command ('OS Command Injection') while uploading a config file via webUI.

πŸ“… Published: July 7, 2025, 9:19 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS4.0

CVE-2025-7121 - Campcodes Complaint Management System complaint-details.php sql injection

A vulnerability was found in Campcodes Complaint Management System 1.0. It has been classified as critical. This affects an unknown part of the file /users/complaint-details.php. The manipulation of the argument cid leads to sql injection. It is possible to initiate the attack remotely. The exploit…

πŸ“… Published: July 7, 2025, 9:02 a.m. πŸ”„ Last Modified: July 8, 2025, 6:29 p.m.

6.9

CVSS4.0

CVE-2025-7120 - Campcodes Complaint Management System check_availability.php sql injection

A vulnerability was found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /users/check_availability.php. The manipulation of the argument email leads to sql injection. The attack may be launched remotely. The …

πŸ“… Published: July 7, 2025, 8:32 a.m. πŸ”„ Last Modified: July 15, 2025, 2:58 p.m.

8.5

CVSS4.0

CVE-2025-3920 - Hard-coded Password in SUR-FBD CMMS

A vulnerability was identified in SUR-FBD CMMS where hard-coded credentials were found within a compiled DLL file. These credentials correspond to a built-in administrative account of the software. An attacker with local access to the system or the application's installation directory could extract…

πŸ“… Published: July 7, 2025, 8:21 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2025-7119 - Campcodes Complaint Management System index.php sql injection

A vulnerability has been found in Campcodes Complaint Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /users/index.php. The manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The…

πŸ“… Published: July 7, 2025, 8:02 a.m. πŸ”„ Last Modified: July 9, 2025, 3:26 p.m.
Total resulsts: 349182
Page 4769 of 34,919
Β« previous page Β» next page
Filters